From 10 December 2026, privacy policies will be required to include additional information about how APP entities use personal information in any automated decision-making tools or processes. The new requirements apply where personal information is used by an APP entity in the operation of a computer program (such as an AI system) to make or do a thing that is substantially and directly related to makinig a decision which could reasonably be expected to significantly affect the rights or interests of an individual (the ADM Obligation). The obligation applies to decisions made after commencement, even if the personal information was collected, or was already being used by the computer program, prior to 10 December 2026.

The Office of the Australian Information Commissioner (OAIC) is expected to release guidance in September 2026. That guidance will be an important indication of the regulator’s interpretation of the new provisions, but as recent submissions in response to the OAIC’s Issues Paper on the ADM Transparency Obligation (Issues Paper) highlight, it may not resolve all issues about the practical scope and application of the obligation. Further, the intended timing for its release will leave organisations with little time before the requirements come into effect. Accordingly, organisations should be turning their minds to the new requirements now and considering how they may need to update their privacy policies.

The elements of the ADM Transparency Obligation

The ADM Transparency Obligation is set out in Australian Privacy Principle (APP) 1.7, and applies where all of the following elements are satisfied:

  1. A decision is being made (including refusing or failing to make a decision) about an individual that could reasonably be expected to significantly affect the rights or interests of that individual.


    AND

  2. The APP entity has arranged for a computer program to be used to:


    (i) solely make that decision; OR


    (ii) do something that is both,

    • (A) substantially; AND
    • (B) directly,

    related to making that decision;

    AND

  3. Personal information about that individual is used in the operation of the computer program to make the decision or do the substantially and directly related thing.

When does a decision ‘significantly affect’ rights or interests?

APP 1.9 provides some examples of the types of decisions that would be covered as significantly affecting rights or interests. These include:

  • A decision made under the provision of an act or legislative instrument to grant, or to refuse to grant, a benefit to the individual. The Explanatory Memorandum (at paragraph 343) gives the example of a decision in relation to granting admission to a country or entitlement to a housing benefit.
  • A decision that affects the individual’s rights under a contract, agreement or arrangement. The Explanatory Memorandum gives the example of a contract for a life insurance policy.
  • A decision that affects the individual’s access to a significant service or support. The Explanatory Memorandum gives the example of access to healthcare services.

In some circumstances it may be more obvious that a decision could have a significant effect on an individual’s rights or interests. For example, if an insurance business uses underwriting algorithms to analyse an applicant’s personal information (such as age, health data, claims history, postcode) to produce a risk score or premium calculation that is used to determine the price of insurance or the terms of cover, that output is arguably affecting a decision that affects the individual’s rights under a policy or contract as it affects the terms on which insurance is offered or the individual’s access to insurance. Similarly, banks using credit-scoring models to approve or decline loan applications will likely fall within scope.

But other scenarios may be less clear. The Explanatory Memorandum notes that computer programs used to target individuals with content and advertisements ‘may have a significant effect on an individual if, for example, it results in differential pricing for provision of, or access to, significant goods or services’.

Importantly, the ADM Transparency Obligation applies regardless of whether the effect on an individual’s rights or interests is adverse or beneficial. The Explanatory Memorandum (at paragraph 340) specifies that the effects of the decision must be more than trivial and must have the potential to significantly influence the circumstances of the individual concerned. The context of the individual also matters, with a decision’s effect on a child or a person experiencing vulnerability potentially being considered significant as compared to its effects on other individuals.

In response to the Issues Paper, the Law Council of Australia submitted that the guidance should make clear that ‘rights or interests’ extend beyond formal legal rights to include practical impacts on a person’s circumstances, opportunities, reputation, livelihood, access to services and ability to participate in society. By contrast, the Business Council of Australia urged a narrower, risk-based interpretation focused on decisions with ‘direct and material consequences’ in areas such as employment, credit, insurance, healthcare, housing, and access to public benefits.

The other related question is what constitutes a decision. Although APP 1.9 makes clear that a decision includes refusing or failing to make a decision, the legislation otherwise does not define its meaning. This leaves some uncertainty for systems that rank, recommend, prioritise or filter opportunities behind the scenes without producing a conventional approval or refusal.

What is a ‘computer program’?

The legislation does not define ‘computer program’ with the Explanatory Memorandum (at paragraph 336) stating that the term is intended to take its ordinary meaning and encompass a broad range of matters, including pre-programmed rule-based processes, AI and machine learning processes to make a computer execute a task. The OAIC also stated in the Issues Paper that the term should be interpreted broadly.

This breadth has raised significant concern with industry. The Business Council of Australia warned that the broad interpretation ‘could lead to inconsistent implementation and unnecessary compliance efforts for low-risk rules-based systems’. The Australian Chamber of Commerce and Industry went further, arguing that the proposed definition ‘could cover everything from AI systems and chatbots to everyday software and word-processing tools’ and that ‘this approach is too expansive and would undermine the purpose of the obligation’.

However, the breadth of the definition of ‘computer program’ does not, by itself, trigger the ADM Transparency Obligation. The computer program must either make the relevant decision on its own, or its output must be ‘substantially and directly’ related to making that decision. The Explanatory Memorandum (at paragraph 337) explains that ‘substantially’ means where the computer program ‘is a key factor in facilitating the human’s decision-making, and ‘directly’ means where ‘the thing has a direct connection with making the decision’. Both requirements must be satisfied.

The obligation does not extend so far as to capture using a computer program for purposes other than facilitating the decision. For example, using a word-processing program to document a decision or a spreadsheet to perform arithmetic. However, a spreadsheet or AI tool that generates a score, ranking, recommendation or summary about an individual may satisfy the threshold depending on how the output is integrated into the decision-making process. Relevant factors are likely to include the degree of reliance placed on the output, whether the output is advisory or determinative, and how deeply the system is integrated into the decision-making workflow.

The Law Council of Australia has urged the Privacy Commission to adopt a ‘substance-over-form’ approach, arguing that ‘formal human involvement is relevant but not determinative’ and that ‘what matters is whether the ADM system is a real and operative factor in the decision, not whether a human nominally signs off’. The Business Council of Australia, by contrast, cautioned that guidance which ‘does not adequately distinguish between fully automated decisions and decisions subject to human review, input or judgement may unintentionally discourage the adoption of governance practices that improve accountability’.

Who has ‘arranged’ for the computer program?

APP 1.7 is directed to the entity that has arranged for the computer program to make or assist in making the relevant decision. The program does not necessarily need to be owned or operated by that entity. This would include an APP entity that procures a computer program to perform the particular decision function, but not a technology provider that hosts software or maintains the infrastructure on which it sits. However, an APP entity could also arrange for a computer program to make a decision where it outsources a business process to a third-party supplier, who then uses a computer program to make decisions in the way it provides that business process to the APP entity.

APP entities relying on external platforms and vendors will need to understand when systems are being used, what systems do in practice and how system outputs are being used. Procurement diligence, contractual information rights and ongoing vendor oversight will be critical.

What must be included in a privacy policy?

Where the elements of APP 1.7 are met, an APP entity must include specified information in its privacy policy regarding the types of personal information used and the kinds of decisions made using the computer program.

APP 1.8 prescribes three items that must be covered:

  1. The kinds of personal information used in the operation of such computer programs
  2. The kinds of such decisions made solely by the operation of such computer programs
  3. The kinds of such decisions for which a thing, that is substantially and directly related to making the decision, is done by the operation of such computer programs.

The Addendum to the Explanatory Memorandum (at paragraph 38) specifies that the level of information required in privacy policies ‘is not expected to include commercial-in-confidence information about automated decision-making systems’. But what level of granular detail is required?

In the Issues Paper, the OAIC acknowledges this challenge and the need to balance providing individuals with enough meaningful information to understand the use of a computer program but avoiding ‘excessive details’ that might obstruct the purpose of transparency and clear communication underlying the ADM Transparency Obligation.

In the previous insurance example, is the insurance business required to identify specific types of personal information (such as location, transaction history or claims information) and how they inform decisions about eligibility, pricing, access and contractual terms? Will they be required to explain the weighting given to different factors? The role of postcode data as a proxy for risk? The fact that the model was trained on historical claims data?

Ultimately, the level of detail required by APP 1.8 will be a question of degree, depending on the nature of the decision, the type of personal information being used, and the computer program itself.

What should organisations be doing now?

With 10 December 2026 approaching and non-binding guidance unlikely to resolve all ambiguities, organisations should be taking practical steps now:

  1. Map decisions and use cases, as well as systems. Identify decisions that affect customers, applicants, employees, patients or other individuals, and identify the systems and personal information used at each stage of those decisions. This includes systems generating scores, rankings, recommendations, eligibility assessments, risk ratings, pricing outputs or similar that feed into decisions.
  2. Record the decision pathway. For each use case, document the personal information used, the program’s output, how that output is used, the role and authority of any human reviewer, the availability and likelihood of override, the affected cohort and the potential consequences of the decision. Do not assume that human-in-the-loop processes are automatically outside scope as the ‘substantially and directly related’ threshold may still be met.
  3. Assess responsibility for third-party systems. Review contracts and procurement processes to ensure the organisation can obtain the information required for its assessment and privacy-policy disclosure.
  4. Apply and document the statutory test. Record the organisation’s reasoning on whether there is a decision, whether the program makes or substantially and directly assists that decision, and whether the decision could reasonably be expected to significantly affect rights or interests.
  5. Review and update privacy policies. Where required, update privacy policies to meet the requirements of APP 1.8. This includes information about the kinds of information used in the operation of the computer program, the kinds of decisions made solely by the program, and the kinds of decisions for which a thing substantially and directly related to making the decision is done by the program. Disclosures should be written in plain, accessible language.
  6. Strengthen internal governance. Ensure governance frameworks adequately address the new ADM Transparency Obligation. This may include updating procurement and vendor due diligence processes to require an assessment of automated decision-making capabilities and disclosure obligations and establishing internal policies for reassessment when a system is introduced, repurposed, or materially modified, or when the organisation changes how it relies on an output.
  7. Monitor the OAIC’s guidance. Complete the inventory and initial scoping now, reassess the analysis when the OAIC releases its guidance, and finalise and publish updated privacy policies before 10 December 2026.